Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.032exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.032 exploits
Exploit-DB
Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)
CVE-2017-17411remotehardware04 ene 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RIESGO
abrir
GitHub PoC771
Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)
CVE-2017-5753MEDIUM04 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC4
Spectre (CVE-2017-5753) (CVE-2017-5715). Not By Me. Collected from Book.
CVE-2017-5753MEDIUM04 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
Exploit-DBVexDay Proof
Xplico - Remote Code Execution (Metasploit)
CVE-2017-16666remotelinux04 ene 2018
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RIESGO
abrir
GitHub PoC
specloli/CVE-2017-17692
CVE-2017-1769204 ene 2018
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-5753MEDIUM04 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
Exploit-DBVexDay Proof
Oracle WebLogic < 10.3.6 - 'wls-wsat' Component Deserialisation Remote Command Execution
CVE-2017-10271HIGHbajo ataqueransomwareremotemultiple03 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC3
forked from https://github.com/s3xy/CVE-2017-10271. Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.Modified by hanc00l
CVE-2017-10271HIGHbajo ataqueransomware03 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
EMC xPression 4.5SP1 Patch 13 - 'model.jobHistoryId' SQL Injection
CVE-2017-14960webappsmultiple03 ene 2018
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL I
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware03 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure
CVE-2017-5753MEDIUMlocalmultiple03 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure
CVE-2017-5715MEDIUMlocalmultiple03 ene 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection
CVE-2018-3810webappsphp03 ene 2018
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection
CVE-2018-3811webappsphp03 ene 2018
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
35RIESGO
abrir
GitHub PoC2
credit to artkond
CVE-2017-3881CRITICALbajo ataque02 ene 2018
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-3881CRITICALbajo ataque02 ene 2018
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
Exploit-DBVexDay Proof
HP Mercury LoadRunner Agent magentproc.exe - Remote Command Execution (Metasploit)
CVE-2010-1549remotewindows01 ene 2018
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote
60RIESGO
abrir
Exploit-DBVexDay Proof
Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)
CVE-2017-5255remotecgi01 ene 2018
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RIESGO
abrir
GitHub PoC
Exploit for CVE-2003-0264 based on pwntools and metasploit's windows/reverse_tcp
CVE-2003-026401 ene 2018
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RIESGO
abrir
Exploit-DB
PHP Melody 2.7.1 - 'playlist' SQL Injection
CVE-2018-5211webappsphp31 dic 2017
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
23RIESGO
abrir
GitHub PoC15
xyzAsian/Janus-CVE-2017-13156
CVE-2017-1315629 dic 2017
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
VulnCheck XDB
local
CVE-2017-1315629 dic 2017
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
Exploit-DB
NetTransport 2.96L - Remote Buffer Overflow (DEP Bypass)
CVE-2017-17968remotewindows29 dic 2017
A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remot
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware28 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware28 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC29
CVE-2017-10271 POC
CVE-2017-10271HIGHbajo ataqueransomware28 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
ALLMediaServer 0.95 - Remote Buffer Overflow (Metasploit)
CVE-2017-17932remotewindows28 dic 2017
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RIESGO
abrir
GitHub PoC143
WebLogic Exploit
CVE-2017-10271HIGHbajo ataqueransomware28 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-17562HIGHbajo ataque27 dic 2017
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
Exploit-DBVexDay Proof
SysGauge Server 3.6.18 - Denial of Service
CVE-2017-15667doswindows27 dic 2017
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafte
23RIESGO
abrir
anteriorpágina 931 / 2668siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.